Template pending legal review. This notice is a draft template and has not yet been reviewed by qualified legal counsel or our Data Protection Officer. It is not in force. Bracketed text marks details to be confirmed.
1. Who we are
Tuppence (tuppence.ai) is a payments platform for developers and AI agents. It is a trading name of [Company legal name] Ltd, a company registered in [England and Wales] (company number [company number]) with its registered office at [registered office address]. We are registered with the Information Commissioner’s Office (ICO) under registration number [ICO registration number].
This notice covers personal data about people who visit this website, join our waitlist, sign up for or use Tuppence, work for the businesses that use Tuppence, or pay those businesses through Tuppence. It is written in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
You can contact our Data Protection Officer at [DPO name or role], [DPO email address].
2. Controller and processor
Depending on the situation, we act in one of two roles:
- As a controller, when we decide why and how personal data is used. This covers the businesses that use Tuppence and their users (names, emails, login and security details), the people we verify when a business goes live, waitlist sign-ups, and people who contact us.
- As a processor, when we handle data about payers — the customers of businesses that use Tuppence — on that business’s behalf. If you paid a business through a Tuppence checkout page, payment link or subscription, that business is the controller and its own privacy notice applies. Our [data processing addendum] governs that processing.
Stripe, which processes card payments and issues Tuppence cards, handles some personal data as a separate controller under its own privacy policy. [Confirm the controller/processor split, including Stripe’s role and our role for payer data, with counsel.]
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account and user | Name, work email, business name, hashed password, two-factor authentication settings, team roles | You, your colleagues |
| Verification (going live) | Business details, and details of directors and owners such as name, date of birth and address, collected through our forms | You; passed to Stripe for its checks |
| Identity documents and selfie | Photo ID and a selfie captured through Stripe Identity | Collected by Stripe and passed to Stripe — not stored by us |
| Payer data (as processor) | Payer name and email, card brand and last four digits, payment amounts and status, subscription and usage records | Payers, through checkout and pay pages; the business using Tuppence; Stripe |
| API and security logs | API requests and responses with secrets redacted, IP address, user agent, audit log of actions in your account | Your use of the dashboard, iPhone app, API and agent tools |
| Waitlist | Email address, and optionally company name, what you are interested in and which page you signed up from | You, through our waitlist form |
| Communications | Support conversations through “Get help”, emails, feedback | You |
This website does not use cookies, analytics or tracking. See our Cookie Policy.
We do not intentionally collect special category data. Stripe Identity processes biometric data to match your selfie to your ID; Stripe does this as [controller / our processor — to be confirmed], and we do not receive or keep the biometric data. [Confirm the condition relied on for biometric processing.]
4. Card data we never see
Full card numbers, CVCs and PINs never reach Tuppence’s systems. Payers type card details straight into Stripe’s own fields on hosted pages, and Stripe holds them. We only keep a token that refers to the card, the card brand and its last four digits. The same applies to Tuppence cards: Stripe holds the full card details.
5. How we use it and our lawful bases
We only use personal data where we have a lawful basis under the UK GDPR. The table below sets out our main purposes where we are the controller.
| Purpose | Lawful basis |
|---|---|
| Creating and running accounts, and providing the dashboard, iPhone app, API and agent tools | Contract, or legitimate interests in providing our services to business customers |
| Verifying businesses and the people behind them, and preventing fraud, money laundering and sanctions breaches | Legal obligation; legitimate interests in preventing crime [confirm] |
| Processing payments, payouts, card spend and cashback, and keeping records | Contract; legal obligation |
| Securing the service, keeping API and audit logs, and investigating incidents | Legitimate interests in protecting our customers and systems |
| Support and service emails (for example, security alerts, payout notices) | Contract; legitimate interests |
| Managing the waitlist and inviting you to live access | Legitimate interests, or consent where required [confirm] |
| Product updates to business contacts | Legitimate interests, or consent where required by the Privacy and Electronic Communications Regulations |
| Complying with regulators, courts and law enforcement | Legal obligation |
Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms. You can ask us for more information about that assessment.
6. Agents and automated decisions
Businesses may connect their own AI agents to Tuppence. Those agents act for the business, which is responsible for them. We do not use your data or payer data to train AI models. [Confirm, and name any AI model providers used by Tuppence itself.]
Some fraud-prevention and verification checks, including Stripe’s, are automated. If an automated decision would have a legal or similarly significant effect on you — for example, declining to verify your identity — you can ask for a person to review it, give your point of view and contest the decision.
7. Who we share it with
We never sell personal data. We share it only where needed, with:
- Stripe, which provides card payment processing, identity verification (Stripe Identity) and card issuing (Stripe Issuing, with [issuing partner]);
- our sub-processors, under contracts that require them to protect it: Google Cloud (hosting), [email provider — Resend] (email delivery) and [others to be confirmed];
- the business you paid, if you are a payer, and systems it connects to Tuppence through webhooks or the API;
- regulators, law enforcement and courts, where the law requires it;
- professional advisers, such as auditors, lawyers and insurers;
- a buyer or investor, if we sell, merge or restructure our business, under appropriate confidentiality protections.
8. Where it is stored
We host Tuppence on Google Cloud in the europe-west2 region (London). Some of our providers, including Stripe and [email provider], may process personal data in other countries, such as the United States. When personal data is transferred outside the UK, we make sure it is protected by:
- UK adequacy regulations for the destination country; or
- the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and any additional safeguards needed.
You can ask for a copy of the relevant safeguards by contacting our Data Protection Officer. [Publish a full sub-processor list with locations.]
9. How long we keep it
We keep personal data only for as long as we need it for the purposes above, including meeting legal, accounting and regulatory requirements.
| Data | Retention period |
|---|---|
| API request logs | 30 days, with secrets redacted |
| Audit logs | [retention period] |
| Account and user data | For the life of the account, then [retention period] |
| Payment, payout and card records | [retention period] after the transaction or the end of the relationship [confirm against legal record-keeping requirements] |
| Verification details we hold | [retention period]. Identity documents and selfies are held by Stripe, not by us. |
| Waitlist sign-ups | Until you are invited and sign up, ask us to remove you, or [retention period], whichever is sooner |
| Support conversations | [retention period] |
When retention periods end, we securely delete or anonymise the data. Where legal proceedings or regulatory investigations are ongoing, we may keep relevant data for longer.
10. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit, hashed passwords, two-factor authentication, restricted API keys, access controls and audit logging. You can read more on our security page. If a personal data breach occurs that is likely to result in a risk to you, we will tell you and the ICO where the law requires.
11. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you and receive a copy;
- rectification of inaccurate or incomplete data;
- erasure, where there is no good reason for us to keep it;
- restrict how we use it in certain circumstances;
- object to processing based on legitimate interests, and to direct marketing at any time;
- data portability, to receive data you provided in a structured, machine-readable format;
- not be subject to solely automated decisions with legal or similarly significant effects, as described in section 6;
- withdraw consent at any time, where we rely on consent.
To exercise a right, contact our Data Protection Officer at [DPO email address]. We may need to verify your identity first. We will respond within one month, or tell you if we need longer because your request is complex. Some rights are limited — for example, we cannot delete records we are legally required to keep.
If you are a payer, the business you paid is the controller of your data. We will pass your request to them and help them respond.
12. Emails and marketing
Service emails — such as security alerts, payout notices and, for payers, receipts and failed-payment reminders sent on a business’s behalf — are not marketing. If you join the waitlist or have an account, we may send you product updates where the law allows. Every such email includes an unsubscribe link.
13. Children
Tuppence is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18 other than as payer data processed for a business.
14. Changes to this notice
We will update this notice when our practices change. If the changes are significant, we will tell account holders by email or in the dashboard before they take effect. The date at the top shows when it was last updated.
15. Contact and complaints
If you have questions about this notice or how we handle your data, contact our Data Protection Officer at [DPO email address]. You can also use our contact page.
If you are unhappy with how we have handled your personal data, you have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk. We would appreciate the chance to put things right first, so please contact us before you do.